PT-2023-21871 · Nextcloud · Nextcloud Android App

Nickvergessen

·

Publicado

2023-03-30

·

Atualizado

2023-04-07

·

CVE-2023-28646

CVSS v3.1

4.4

Média

VetorAV:P/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Android versions 3.7.0 through 3.24.0
Description The Nextcloud Android app has a security issue that allows an attacker with access to an unlocked physical device to bypass the Pin/passcode protection using a third-party app. This enables the attacker to view meta information such as sharer, sharees, and activity of files.
Recommendations For versions 3.7.0 through 3.24.0, upgrade the Nextcloud Android app to version 3.24.1 to resolve the issue.

Exploit

Correção

Improper Preservation of Permissions

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28646
GHSA-C3RF-94H6-VJ8V

Produtos afetados

Nextcloud Android App